US2025384125A1PendingUtilityA1

Secure system automated design device, secure system automated design method, and storage medium

Assignee: NEC CORPPriority: Jun 14, 2024Filed: May 30, 2025Published: Dec 18, 2025
Est. expiryJun 14, 2044(~17.9 yrs left)· nominal 20-yr term from priority
Inventors:Ryosuke Hotchi
G06F 2221/034G06F 21/552
65
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A secure system automated design device accepts a design requirement of a system; generates a system configuration plan that satisfies the design requirement; derives threats that are present in the system configuration plan, attack paths that are constituted by a chain of the threats, and countermeasures that are implemented with respect to the threats; and derives a threat consideration priority that represents a priority with which the threats are to be considered, and an attack path consideration priority that represents a priority with which the attack paths are to be considered.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A secure system automated design device comprising:
 at least one memory configured to store instructions; and   at least one processor configured to execute the instructions to:
 accept a design requirement of a system; 
 generate a system configuration plan that satisfies the design requirement; 
 derive threats that are present in the system configuration plan, attack paths that are constituted by a chain of the threats, and countermeasures that are implemented with respect to the threats; and 
 derive a threat consideration priority that represents a priority with which the threats are to be considered, and an attack path consideration priority that represents a priority with which the attack paths are to be considered. 
   
     
     
         2 . The secure system automated design device according to  claim 1 , wherein the at least one processor is configured to execute the instructions to:
 derive the attack path consideration priority for all of the threats that are present in the system configuration plan by referring to security model information; and   derive the attack path consideration priority for all of the attack paths based on information about the threats and the countermeasure that is present in the system configuration plan.   
     
     
         3 . The secure system automated design device according to  claim 1 , wherein the at least one processor is configured to execute the instructions to:
 derive the attack path consideration priority for all of the threats that are present in the system configuration plan by referring to security model information, while also deriving a threat concretization relationship consideration priority that represents a priority with which a relationship between the threats is to be considered; and   derive the attack path consideration priority for all of the attack paths based on information about the threats, the countermeasures, and the relationships between the threats that is present in the system configuration plan.   
     
     
         4 . The secure system automated design device according to  claim 1 , wherein the at least one processor is configured to execute the instructions to:
 accept a tolerance value of a security of the system;   compare the attack path consideration priority for each attack path and the tolerance value; and   determine that the system configuration plan is not unsecure if all of the attack path consideration priorities are less than the tolerance value.   
     
     
         5 . The secure system automated design device according to  claim 4 , wherein the at least one processor is configured to execute the instructions to:
 compare the attack path consideration priority of each attack path with the tolerance value; and   do not derive the countermeasure for an attack path in which the attack path consideration priority is less than the tolerance value.   
     
     
         6 . The secure system automated design device according to  claim 2 , wherein the at least one processor is configured to execute the instructions to:
 derive the attack path consideration priority by multiplying the threat consideration priority derived for all of the threats constituting the attack path; and   set the threat consideration priority of the threats for which a countermeasure has been derived to a value lower than an attack path threshold.   
     
     
         7 . The secure system automated design device according to  claim 3 , wherein the at least one processor is configured to execute the instructions to:
 derive the attack path consideration priority by multiplying the threat consideration priority derived for all of the threats constituting the attack path, and a threat concretization relationship consideration priority derived for the relationships between all of the threats constituting the attack path; and   set the threat consideration priority of the threats for which a countermeasure has been derived to a value lower than an attack path threshold.   
     
     
         8 . A secure system automated design method that causes a secure system automated design device to perform:
 accepting a design requirement of a system;   generating a system configuration plan that satisfies the design requirement;   deriving threats that are present in the system configuration plan, attack paths constituted by a chain of the threats, and countermeasures that are implemented with respect to the threats; and   deriving a threat consideration priority that represents a priority with which the threats are to be considered, and an attack path that are consideration priority that represents a priority with which the attack paths are to be considered.   
     
     
         9 . The secure system automated design method according to  claim 8 , further comprising:
 deriving the attack path consideration priority for all of the threats that are present in the system configuration plan by referring to security model information; and   deriving the attack path consideration priority for all of the attack paths based on information about the threats and the countermeasure that is present in the system configuration plan.   
     
     
         10 . The secure system automated design method according to  claim 8 , further comprising:
 deriving the attack path consideration priority for all of the threats that are present in the system configuration plan by referring to security model information, while also deriving a threat concretization relationship consideration priority that represents a priority with which a relationship between the threats is to be considered; and   deriving the attack path consideration priority for all of the attack paths based on information about the threats, the countermeasures, and the relationships between the threats that is present in the system configuration plan.   
     
     
         11 . The secure system automated design method according to  claim 8 , further comprising:
 accepting a tolerance value of a security of the system;   comparing the attack path consideration priority for each attack path and the tolerance value; and   determining that the system configuration plan is not unsecure if all of the attack path consideration priorities are less than the tolerance value.   
     
     
         12 . The secure system automated design method according to  claim 11 , further comprising:
 comparing the attack path consideration priority of each attack path with the tolerance value; and   doing not derive the countermeasure for an attack path in which the attack path consideration priority is less than the tolerance value.   
     
     
         13 . The secure system automated design method according to  claim 9 , further comprising:
 deriving the attack path consideration priority by multiplying the threat consideration priority derived for all of the threats constituting the attack path; and   setting the threat consideration priority of the threats for which a countermeasure has been derived to a value lower than an attack path threshold.   
     
     
         14 . The secure system automated design method according to  claim 10 , further comprising:
 deriving the attack path consideration priority by multiplying the threat consideration priority derived for all of the threats constituting the attack path, and a threat concretization relationship consideration priority derived for the relationships between all of the threats constituting the attack path; and   setting the threat consideration priority of the threats for which a countermeasure has been derived to a value lower than an attack path threshold.   
     
     
         15 . A non-transitory storage medium storing a program that causes a computer to execute:
 accepting a design requirement of a system;   generating a system configuration plan that satisfies the design requirement;   deriving threats that are present in the system configuration plan, attack paths that are constituted by a chain of the threats, and countermeasures that are implemented with respect to the threats; and   deriving a threat consideration priority that represents a priority with which the threats are to be considered, and an attack path consideration priority that represents a priority with which the attack paths are to be considered.

Join the waitlist — get patent alerts

Track US2025384125A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.